The Dirty Pipe vulnerability, CVE-2022-0847, is a local privilege escalation vulnerability affecting the Linux kernel[1]. This vulnerability allows an attacker to overwrite files on the operating system, leading to potential system compromise. The vulnerability was discovered by security researcher Max Kellermann and disclosed in March 2022. It is named "Dirty Pipe" because it resembles the "Dirty Cow" exploit that affected older kernel versions.
The impact of the Dirty Pipe vulnerability is significant as it affects Linux kernel versions 5.8 and newer. Patches have been released in Linux versions 5.16.11, 5.15.25, and 5.10.102[6] to address this issue. The Common Vulnerability Scoring System (CVSS) score for CVE-2022-0847 is 7.8, indicating a high severity level.
This vulnerability underscores the importance of timely software updates and security patches to protect systems from potential exploits and unauthorized access.